Related Links

Related Stories

  • Twitter email account hack highlights cloud dangers
    Imperva, a data security specialist, says that last week's hacking of a Twitter senior executive's email account - details of which are now fully emerging - was the result of a combination of poor security practices and safeguards.
  • Twitter company files leaked in Cloud Computing security failure
    Twitter has once again been hit by a lapse of security, this time with a hacker posting a set of internal company documents from the Twitter site and service, lifted from the GoogleApps online data sharing and collaboration system.
  • The information security industry needs to offer more than just security, says Secerno COO
    The information security industry needs to adapt to cloud computing, not the other way around, says Secerno’s founder and COO, Paul Davie, who talks to Infosecurity about how offering security is no longer enough
  • Jericho Forum links with Cloud Security Alliance
    Hard on the heels of unveiling Cloud Cube, its four-dimensional best practice model for cloud computing security in April, security industry association the Jericho Forum has linked with the Cloud Security Alliance (CSA), a not-for-profit vendor group.
  • Forrester questions the security of cloud computing
    With the economic downturn, cloud computing is seen as a way to improve operational efficiency, reduce headcounts and help with the bottom line, but according to the report from Massachusetts-based Forrester Research on cloud computing, organisations should not jump on the ‘cloud wagon’ before considering security and privacy concerns.

News

Information security experts support CAM initiative

08 February 2010

The Common Assurance Metric (CAM) industry initiative was launched today as a system of assuring security within cloud computing

Information security stakeholders in the private and public sectors are collaborating on the CAM initiative, which is to be implemented on a global scale. CAM developers are working to ensure that safety measures in cloud computing and third party service providers are standardised, providing a quantifiable method of comparing hosts.

The Cloud Security Alliance are in favour of the initiative, executive director, Jim Reavis said. "With today's complex IT architectures and heavy reliance upon third party providers, there has never been a greater demand for transparency and objective metrics for attestation, The Common Assurance Metric framework has great promise to address this demand and the Cloud Security Alliance is proud to support this initiative and align our own cloud security metrics research with it."

Matt Broda, Microsoft senior security strategist, supports the project and has suggested that the key players in the industry must work together in order to make the initiative work. Broda said: "Microsoft is committed to delivering secure, private, and reliable computing experiences.  In today's interconnected world, trustworthiness of computing solutions depends on many interdependent components and requires broad industry collaboration.  We look forward to contributing to the work on Common Assurance Metric.

The framework of CAM is set to be delivered by the end of 2010 and will be welcomed by the Information Security Awareness Forum (ISAF). ISAF's chairman, David King, said: “ISAF is committed to improving accessibility of advice through the promotion of consistent messages to help protect individuals and businesses alike.  The Common Assurance Metric is a bold initiative that aspires to provide greater consistency in the security of cloud computing services. This will help to make the Internet a safer place for business and pleasure - an objective which the ISAF very much supports.”

 

This article is featured in:
Compliance and Policy Internet and Network Security Security Training and Education

 

Comment on this article

You must be registered and logged in to leave a comment about this article.